Opens in a new tab
vmblog logo 2024 wht (updated)

Intel 471 2024 Predictions: Looking Ahead – Cybersecurity Challenges in 2024

Share: 

David Marshall | Published: January 9, 2024

vmblog-predictions-2024 

Industry executives and experts share their predictions for 2024.  Read them in this 16th annual VMblog.com series exclusive.

Looking Ahead: Cybersecurity Challenges in 2024

By Michael DeBolt, Chief Intelligence Officer, Intel 471

The cybercriminal underground was more active than ever in 2023. Intel 471 analysts study malware samples, data breaches, software vulnerabilities and conversations between threat actors to understand how bad actors are undermining systems and found that organizations saw continued risks from persistent attack vectors including information-stealer malware distributed by initial access brokers (IABs), or those who specialize in breaking into networks and selling that access. Phishing campaigns remained a persistent method to steal credentials and sometimes session tokens that can be parlayed into access. Vulnerability exploitation also rose as one of the most popular methods to compromise organizations. While threat actors occasionally leveraged zero-day vulnerabilities, which tend to generate headlines, the truth is most organizations are caught out by n-day vulnerabilities where patches have been available for some time. This cumulatively resulted in an environment where one of the biggest risks for organizations is a ransomware or extortion attack.

Here is an overview of what’s ahead in the cybersecurity and the criminal underground in 2024.

Supply Chain Risks Abound

We expect to see threat actors look for opportunities to attack through supply chains. Most organizations do not work in isolation and increasingly rely on third-party partners, suppliers and vendors. Cybercriminals see opportunities in these relationships and target weaknesses to extract data. One organization may have rock solid security, but threat actors will look to its suppliers and others that have existing relationships for a side door in.

Consequently, if one business maintains robust cybersecurity standards but works with a less secure vendor, that third party has the capability to provide an attacker with an avenue to breach the organization’s defenses. With a foothold in a vendor’s network, threat actors can then pivot through the supply chain to the originally more secure network using that trusted relationship. These attacks can have disastrous knock-on effects. Third-party risk cannot be completely eliminated, but there are steps that can help detect and mitigate it. These include continuously monitoring and assessing the security posture of suppliers, employing zero-trust principles and leveraging threat intelligence to stay informed of emerging threats, vulnerabilities and tactics, techniques and procedures (TTPs).

Law Enforcement Will Pressure ‘The Com’

Dozens of attacks by English-speaking threat actors drew attention to a long-running threat actor group loosely known as “The Community” or “The Com.” The group and subgroups (also referred to as Scattered Spider, Muddled Libra, Starfraud, UNC3944, Scatter Swine, Roasted 0ktapus, 0ktapus) comprise a large number of mostly mid-to-lower level skilled threat actors but with a small subset of highly technically capable actors who have been evolving and upskilling for several years.

One such group was LAPSUS$. It focused on subscriber identity module (SIM) swapping, gaming hacks, swatting and cryptocurrency theft. Except for telecommunications companies affected by SIM swapping, it generally wasn’t considered a threat to enterprise security. That changed in 2023 with unending attacks and intrusions. Some with links to The Com began working with the ALPHV aka BlackCat RaaS group. This marked a somewhat rare alliance, as ransomware actors – who are mostly centered in Eastern Europe – have at times said they do not want to work with English speakers. The ransomware and extortion attacks conducted against MGM Resorts and Caesars Entertainment were believed to be linked to these threat actors. The Com also has been linked to attacks against business process outsourcing (BPO) companies and identity providers, running highly effective phishing campaigns that capture login credentials. Some group members use sharp social engineering skills to manipulate help desks into resetting multifactor authentication (MFA) tokens or reassigning them to new devices.

Although these threat actors fail many times, they are extremely persistent. When they gain access, they often read internal documentation on processes and procedures and use that knowledge to achieve deeper access. They’ve even joined organizations’ incident response calls. These actors will present a continued threat through next year, although expect law enforcement to exert pressure and possibly make arrests in 2024. These prospects, however, are tempered by the belief that some threat actors are likely minors, which limits options available to courts.

Web-Facing Enterprise Software Is a Target

Ransomware groups quickly acted upon vulnerabilities in web-facing appliances and enterprise software this year. In May 2023, the CLOP cybercrime group exploited zero-day vulnerabilities in Progress Software’s MOVEit managed file transfer software to execute one of the largest mass data breaches of all time with more than 2,500 organizations affected. The attack did not involve file-encrypting ransomware – instead, CLOP exploited internet-facing MOVEit portals and extracted the data stored. It then held organizations for ransom. As many as half of the health care organizations paid ransoms to prevent data from being posted on CLOP’s data leak site.

In October 2023, the disclosure of a vulnerability in Citrix’s NetScaler Application Delivery Controller (ADC) and Gateway products saw ransomware actors quickly find vulnerable devices and attack. This will be a threat throughout next year as groups buy or fund research into software vulnerabilities in commonly used software. Organizations must fully account for their software assets and understand the breadth of their own attack surfaces, especially via knowing what applications attackers can see using device search engines such as Shodan and Censys. Organizations also must understand the operational impact of taking those services offline if there’s a new vulnerability and configure services in a more secure way or replace them with more secure alternatives.

##

ABOUT THE AUTHOR

Michael DeBolt 

Michael DeBolt is the Chief Intelligence Officer at Intel 471, leading a globally diverse team of threat intelligence experts tracking cyber threat actors, and producing intelligence to protect customers. Prior to Intel 471, he served as the U.S. representative and head of cybercrime intelligence at Interpol. He also led national security cyber counterintelligence operations as a special agent at the U.S. Naval Criminal Investigative Service. He’s a U.S. Marine Corps veteran who served combat tours of duty as an infantry scout leader.